Messaging Privacy · Australia

Private messaging apps Australia — Signal, Threema, WhatsApp and what each actually does.

Every major messaging app claims to be "secure." This guide explains what end-to-end encryption actually means, what metadata each app collects, and which apps Australian professionals, journalists, and privacy-conscious users should trust.

What to know first

End-to-end encryption protects the content of your messages from being read in transit. It does not protect metadata: who you messaged, when, how often, and from what device. For most people, Signal offers the best combination of strong encryption and minimal metadata collection. For those who need to communicate without their phone number being linked to their account, Threema is the better choice. WhatsApp encrypts content but retains significant metadata and shares it with Meta.

What "private messaging" actually means

The phrase "end-to-end encrypted" appears in the marketing of most major messaging apps — WhatsApp, iMessage, Signal, Telegram (partially), and Threema all use it. But encryption is only one dimension of messaging privacy. The questions that matter beyond encryption are:

These questions produce very different answers for each app — and understanding those answers is the point of this guide.

App-by-app breakdown for Australian users

Signal — the benchmark for private messaging

Signal is a free, open-source messaging app operated by the Signal Foundation, a US-based nonprofit. It uses end-to-end encryption for all messages, calls, and file transfers. More importantly, it collects almost no metadata: Signal does not store who you message, when, how often, or from what IP address. The only information Signal retains is the date an account was created and the date it last connected to Signal servers — a fact that has been confirmed multiple times in court proceedings.

Signal requires a phone number to register, though you can now create a username and share that instead of your number. The app is independently audited, and the protocol is considered state-of-the-art. For day-to-day private communications — legal discussions, medical conversations, financial matters, source-sensitive journalism — Signal is the standard recommendation.

Best for: Professional and personal private communications. Lawyers, journalists, medical professionals, executives, and privacy-conscious individuals.

Threema — truly anonymous messaging

Threema is a Swiss-based messaging app that requires no phone number, no email address, and no personal information of any kind to create an account. You generate a random Threema ID, share it with trusted contacts, and your messaging account is entirely unlinked from your real identity.

Threema is a paid app (a one-time purchase), which means there is no advertising business model. It is subject to Swiss privacy law (stricter than Australian or US law), is independently audited, and has been used by journalists, activists, lawyers, and government officials who need truly anonymous communications. We stock Threema licences and pre-configure the app on prepared devices.

Best for: Situations where even Signal's knowledge of your phone number is a risk. Anonymous source contact for journalists, identity-sensitive professional communications, and anyone operating in a high-risk environment.

WhatsApp — encrypted content, but significant metadata

WhatsApp uses end-to-end encryption for message content, using the Signal Protocol licenced from Open Whisper Systems. The message text itself is encrypted and not readable by Meta. However, WhatsApp collects extensive metadata — contact lists, usage patterns, when and how often you message specific contacts, device identifiers, and IP addresses — and shares this with the Meta advertising ecosystem.

Under Meta's privacy policy, this data can be used for advertising targeting, shared across Meta's family of products, and is retained on Meta's infrastructure where it can be accessed under legal compulsion. WhatsApp has cooperated with law enforcement data requests globally. The content is protected; the context is not.

WhatsApp is appropriate for low-stakes social communications where the network effect (everyone is already there) outweighs the privacy trade-off. It is not appropriate for communications that need genuine privacy.

Best for: Everyday social coordination where network ubiquity is more important than strong privacy. Not suitable for sensitive professional, legal, medical, or source-sensitive communications.

iMessage — better than SMS, worse than Signal

Apple's iMessage uses end-to-end encryption between Apple devices and provides a significantly better baseline than SMS or standard email. However, iMessage has important limitations. Messages backed up to iCloud are encrypted at rest but Apple holds the encryption keys — meaning iCloud backups can be and have been produced in response to law enforcement requests. iMessage metadata (who you message, when) is retained by Apple. And iMessage only works between Apple devices — any message sent to a non-iPhone reverts to unencrypted SMS.

Apple also operates a cloud-based infrastructure that, like any cloud service, is subject to legal process in the jurisdictions where it operates. Australia's Assistance and Access Act 2018 gives domestic law enforcement tools to compel assistance with data access from Australian-connected providers.

Best for: Casual communications between Apple users who want better-than-SMS privacy without switching apps. Not suitable for genuinely sensitive communications.

Telegram — not end-to-end encrypted by default

Telegram is frequently mischaracterised as a privacy-focused messaging app. Standard Telegram chats are not end-to-end encrypted — they are encrypted in transit between your device and Telegram's servers, but Telegram itself can read them. Only "Secret Chats" are end-to-end encrypted, and group chats are never end-to-end encrypted regardless of settings.

Telegram collects and stores message content by default, retains metadata, and has produced user data to law enforcement in multiple jurisdictions. It is not a private messaging app in any meaningful sense for most use cases.

Best for: Public communities, channels, and social coordination where privacy is not required. Not suitable for private communications.

Side-by-side comparison

FeatureSignalThreemaWhatsAppiMessageTelegram
Message content encryptedYesYesYesYes*Secret chats only
Metadata retainedMinimalMinimalExtensiveSomeExtensive
Phone number requiredTo registerNoYesYesYes
Open sourceYesCore auditedNoNoPartial
Business modelNonprofitSubscriptionAdvertisingHardware salesAdvertising planned
Server jurisdictionUSASwitzerlandUSA (Meta)USA (Apple)UAE
Law enforcement data producedEffectively nothingVery limitedMetadata yesWith iCloud backupYes
CostFreeOne-time purchaseFreeFree (Apple only)Free

* iMessage is E2E only between Apple devices. iCloud backups may undermine this encryption if the backup key is held by Apple.

Choosing the right app for your situation

Journalists and media

Threema for initial source contact (no phone number linkage). Signal for ongoing communications with trusted sources. Never use WhatsApp or standard SMS for source-sensitive material. Consider our journalism secure phone guide for the full setup.

Legal professionals

Signal for lawyer-client communications where privilege must be maintained. Threema where identity-linked communications are a risk. Do not use WhatsApp, iMessage with iCloud backup, or email for privileged communications. The metadata WhatsApp retains can undermine privilege in practice.

Medical professionals

Signal for patient-related communications. Australia's Privacy Act and health records legislation require that personal health information be protected — WhatsApp's metadata collection and Meta data sharing are incompatible with this requirement for identified patient communications.

Business executives

Signal for sensitive business communications. Threema for communications where the contact's ability to identify you should be minimised. Both configured via our Encrypted Comms Setup service on prepared devices. See our executive secure phones page for the full picture.

Politicians and government officials

Signal for political communications that should not be accessible to opposition research, media, or foreign intelligence. Threema for whistleblower and source contact. The two-device model — a public phone for official work, a secure phone for sensitive political communications — is the recommended approach. See our politicians secure phone guide.

Everyone else

Signal is free, easy to use, and available on iOS, Android, and desktop. There is no downside to using it for all communications. Moving your private conversations to Signal is one of the highest-impact privacy changes an individual can make, regardless of their specific threat model.

The operating system matters as much as the app

Choosing Signal over WhatsApp is a meaningful improvement. But the operating system running beneath your messaging app also collects data — telemetry, location history, advertising identifiers, and app usage metadata — that can reveal who you communicate with and when, regardless of which messaging app you use.

GrapheneOS removes these background data flows from the OS level. On a Privacy Devices prepared phone running GrapheneOS, Signal's privacy guarantees are fully realised because the operating system is not simultaneously leaking metadata that undermines them. A stock Android phone running Signal is significantly more private than the same phone running WhatsApp — but a GrapheneOS phone running Signal is more private still.

Our prepared devices ship with Signal pre-installed and configured, Threema licenced on request, and the operating system hardened so that neither app's privacy is undermined by what is running underneath it. See our secure messaging guide for the detailed setup instructions.

Australian law and encrypted messaging

There is no Australian law that prohibits using end-to-end encrypted messaging apps. Signal, Threema, and WhatsApp are all lawful communication tools. The Telecommunications (Interception and Access) Act 1979 governs what law enforcement can compel from carriers and service providers — it does not prohibit the use of encrypted communications by individuals or organisations.

The Assistance and Access Act 2018 (sometimes called the "encryption bill") gives the Australian government tools to compel technical assistance from domestic providers, including potentially requiring the implementation of backdoors in some circumstances. This is a complex area of law, but it does not make encrypted messaging illegal or create criminal liability for using it.

For a detailed discussion of the legal landscape, see our guide on whether encrypted phones are legal in Australia.

Private messaging apps Australia — FAQ

What is the most secure messaging app in Australia?

Signal offers the strongest combination of security and usability for most Australians. It uses state-of-the-art end-to-end encryption, collects almost no metadata, is fully open source, and is operated by a nonprofit with no advertising incentive. For situations where even linking your phone number to your account is a risk, Threema — which requires no phone number — is the strongest choice.

Is Signal legal in Australia?

Yes. Signal is a lawful communication tool in Australia. There is no law that prohibits using end-to-end encrypted messaging apps. Signal is used by journalists, lawyers, medical professionals, politicians, and privacy-conscious individuals across Australia without any legal issue.

Is WhatsApp private in Australia?

WhatsApp encrypts message content end-to-end, but it collects extensive metadata and shares it with Meta. Under WhatsApp's privacy policy, information about who you message, when, how often, and from what device flows into Meta's advertising systems. This metadata has been produced in law enforcement proceedings globally. WhatsApp is not a private messaging app in the full sense — it protects message content but not the context around it.

What messaging app do journalists use in Australia?

Signal is the standard recommendation for journalism that involves confidential sources. For initial source contact where the journalist's phone number should not be known to the source, Threema (which requires no phone number to use) is preferred. The Reuters Digital Security Lab and international press freedom organisations recommend Signal and Threema for source-sensitive communications.

Can the Australian government read Signal messages?

Signal has demonstrated repeatedly — in court proceedings that produced public records — that it cannot comply with broad government data requests because it does not retain the information. The Australian government could compel Signal to produce what it has, but what it has is essentially nothing: account creation date and last connection date. Message content, contacts, and metadata do not exist on Signal's servers.

Does Threema work in Australia?

Yes. Threema works on iOS and Android in Australia, connects via standard internet, and does not require any VPN or special network configuration. The one-time purchase can be made from the App Store or Google Play. We also stock Threema licences directly, pre-configured on our prepared devices.

What messaging app should a doctor use in Australia?

Signal is the appropriate choice for Australian medical professionals who need to discuss patient information via messaging. WhatsApp's metadata collection and Meta data sharing are incompatible with the requirements of the Privacy Act and health records legislation for identified patient communications. Signal's minimal metadata retention is appropriate for these purposes.

Private messaging needs a private device.

Signal and Threema pre-installed, configured, and running on GrapheneOS. Dispatched from Australia.

Browse Secure Devices → Threema Licence